SEGUC17/Foobar

password sent on adding admin in the console

Opened this issue · 4 comments

A. Severity: ( high)

B. Reported: by Mina

C. Description: On adding an admin with an email (or even with any text) the password is sent in the console while I should only get it from the email sen to me

  1. login as an admin
  2. add admin with a text not an email
  3. press add admin
  4. see the console, you find all the data of this admin (including the password ! )

D. Expected result: The password should not be sent in the console, I should only get it from the email sent to me

It will only appear to the admin who added him so that's okay

As an admin, I should not know the passwords of users or any other admins

as an admin, you won't get access to any profile of a user or a SP don't worry

But with this info , email and password (that I got in the console) I can login with these info